BrickStor CSfC DAR — Classified Data at Rest, Ready for the Fight
Data at rest protection designed to the NSA CSfC Capability Package, combined with the BrickStor platform's immutable audit and integrity monitoring. Higher performance and more deployment flexibility than Type 1, releasable for allied and coalition use, and engineered for tactical, shipboard, and airborne missions.
Classified missions can't wait for yesterday's hardware
The adversary is moving at commercial speed. Classified data protection has to move with them — without compromising the rigor the NSA CSfC program demands. BrickStor CSfC DAR is engineered to deliver both, on hardware you can actually field this year.
Eliminate Type 1 encryption bottlenecks.
CSfC DAR on commercial NVMe Gen 5 flash delivers read and write performance Type 1 devices can't match — sustained throughput for ingest-heavy workloads, real-time analytics, and high-rate recording at the edge. The architecture is releasable for allied and coalition operations, available in multiple form factors, and refreshes on commercial cadence rather than waiting on the Type 1 supply chain.
Layered encryption plus classified-grade accountability.
Dual-layer commercial encryption protects classified data at rest. On top of that, the BrickStor platform adds immutable audit and integrity monitoring — so the platform protects against both the stolen-device scenario and the insider-misuse scenario.
Tactical, shipboard, airborne, expeditionary.
Classified missions increasingly operate outside SCIFs and fixed data centers. BrickStor CSfC DAR is engineered for forward-deployed and mobile platforms — with ruggedized options and a commercial refresh cadence matched to how fast missions evolve.
What CSfC on BrickStor delivers to program offices
Commercial NVMe Gen 5 flash delivers sustained throughput Type 1 can't match — for ingest, analytics, and recording at the edge.
Two independent, NSA-approved encryption layers protect classified data at rest.
Layered encryption, immutable audit, and integrity monitoring in a single accredited stack.
In Common Criteria evaluation now; Components listing expected Q4 2026.
Most CSfC DAR stops at encryption.
BrickStor delivers audit and accountability.
The CSfC capability package covers the encryption architecture. It doesn't detect tampering of classified data, and it doesn't produce the audit trail an IG will ask for. BrickStor does — on the same accredited platform.
Performance, flexibility, and allied use Type 1 can't match
Type 1 devices remain essential for specific use cases — but they cap performance, restrict deployment, and carry significant consequence if a device is lost or compromised in the field. CSfC DAR on BrickStor delivers higher read and write throughput on commercial NVMe, releases cleanly for allied and coalition operations where Type 1 is restricted, and limits exposure if hardware is lost — a cleared zeroize, not an international incident.
More than encryption — audit and accountability
Most CSfC DAR offerings stop at the encryption layer. BrickStor adds the accountability classified missions require — immutable audit supporting investigations and integrity monitoring defending against tampering.
Built for classified data at the edge
CSfC Data at Rest Protection
NSA CSfCArchitecture designed to the NSA Commercial Solutions for Classified (CSfC) Data at Rest Capability Package protects classified data at rest using dual layered commercial encryption.
Classified Edge Deployment
EdgePurpose-built for tactical, mobile, and edge environments where classified data must be protected outside of traditional SCIFs and data centers.
Layered Encryption
CoreDual-layer encryption architecture meets CSfC Data at Rest Capability Package requirements for protecting classified information on commercial hardware.
High-Speed Data Recorder
OptionalOptional High-Speed Data Recorder (HDR) functionality can be added to the CSfC DAR platform — combining classified-ready data protection with lossless high-rate recording for ISR, SIGINT, radar, and test-range missions.
Explore BrickStor HDRRackTop SHIELD
CSfC ComponentDesigned to be the outer layer, handling the Authorization Acquisition (AA) function for CSfC listed drives. Ships in this platform and is available separately.
Explore RackTop SHIELDRackTop SPEAR
CSfC ComponentSoftware-based Full Drive Encryption implementing both the AA and EE functions, designed to be the inner encryption layer. Ships in this platform and is available separately.
Explore RackTop SPEARHigh-Performance NVMe
PerformancePCIe Gen 5 NVMe flash delivers the bandwidth and IOPS required for the most demanding classified workloads — sustained ingest, real-time analytics, and high-rate recording at the tactical edge.
Immutable Audit & Accountability
CoreImmutable, tamper-evident audit logging provides accountability for all access to classified data, supporting security reviews, SIRs, and incident investigations.
Deployed where the mission demands
Tactical Edge
Protect classified data on forward-deployed, mobile, and expeditionary platforms where physical security is limited.
Shipboard & Maritime
Classified data storage and protection for naval vessels and maritime platforms operating in contested environments.
Airborne Systems
Secure classified data capture and storage for airborne ISR, C2, and mission systems.
Why CSfC for classified data at rest
The NSA CSfC program enables agencies and commands to use layered commercial encryption to protect classified data — delivering higher performance, broader deployment flexibility, and use cases (including allied and coalition operations) that traditional Type 1 encryption devices can't support.
Frequently asked questions
- CSfC (Commercial Solutions for Classified) Data at Rest is an NSA program that enables the use of layered commercial encryption products to protect classified data at rest — an alternative to Type 1 encryption devices that delivers higher performance, broader deployment flexibility, and releasability for allied and coalition use.
- CSfC architectures protect classified data up to Top Secret; the level a given deployment supports is determined by its registered solution architecture. BrickStor CSfC DAR is designed to the CSfC Data at Rest Capability Package for classified data on commercial hardware in tactical and edge environments. Contact RackTop to discuss the classification levels and architecture for your program.
- Type 1 devices remain essential for specific use cases. CSfC is typically chosen when programs need higher read and write performance than Type 1 can deliver, the flexibility to operate with allied and coalition partners, and lower consequence-of-loss if hardware is compromised in the field — a cleared zeroize event rather than the incident response a lost Type 1 device triggers. CSfC also brings commercial refresh cadence and a lower total cost of ownership without lowering the bar on protection of classified information at rest.
- BrickStor CSfC DAR adds the dual-layer encryption architecture of the NSA CSfC Data at Rest Capability Package on top of the BrickStor SP Cyberstorage platform. It is specifically designed for environments where classified data must be stored and protected outside of traditional secure facilities.
- Yes. BrickStor CSfC DAR is engineered for tactical, mobile, shipboard, airborne, and expeditionary deployments where classified data must be protected with limited physical security infrastructure.
Independently recognized. Externally validated.






Gartner named RackTop a sample vendor when it introduced the Cyberstorage category (2021)
See the category history →ESG Economic Validation: less than half the cost of alternative NAS solutions
Read the economic validation →ESG Technical Validation: stops ransomware at the storage layer in real time
Read the technical validation →Four U.S. patents on the Cyberstorage architecture
Review the patents →Validated with HPE, IBM, Nutanix, and more
See the technology alliances →
Classified Data Protection, Ready for the Edge
BrickStor CSfC DAR delivers classified data at rest protection designed to the NSA CSfC DAR Capability Package, with the performance and flexibility commercial hardware brings — releasable for allied use, lower consequence-of-loss in contested environments, and immutable audit and integrity monitoring on top.
NSA CSfC Component listing for AA and AA+EE expected in Q4 2026.
